This day 02:07 06:07 10:08 14:08 18:08 22:09
Info  2026-08-30 18:08Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-08-30 — Breach Claims Validated, Scraping Defense

Executive summary: The most significant development today is independent validation of the Manchester Airports Group data breach: BleepingComputer confirmed at least one traveller's stolen record and found that sample data exposed by FulcrumSec contains more detailed customer, booking, and travel information than MAG initially disclosed. No genuinely new developments emerged on the ServiceNow, Hugging Face, Chrome/Edge extension, or Claude session-hijack stories beyond what was already covered. A defensive article on IP-intelligence-based anti-scraping techniques rounds out today's intake.

Top items

Themes

Breach disclosure lag. The Manchester Airports Group development is the latest example this fortnight of an organisation initially downplaying breach scope, only for third-party validation to reveal more extensive data exposure. This pattern has appeared in multiple recent incidents (McKesson, Hasbro, Berlin state network) and underscores the value of independently verifying attacker claims rather than relying solely on victim disclosures.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db